{"id":"CVE-2023-27581","summary":"github-slug-action vulnerable to arbitrary code execution","details":"github-slug-action is a GitHub Action to expose slug value of GitHub environment variables inside of one's GitHub workflow. Starting in version 4.0.0` and prior to version 4.4.1, this action uses the `github.head_ref` parameter in an insecure way. This vulnerability can be triggered by any user on GitHub on any workflow using the action on pull requests. They just need to create a pull request with a branch name, which can contain the attack payload. This can be used to execute code on the GitHub runners and to exfiltrate any secrets one uses in the CI pipeline. A patched action is available in version 4.4.1. No workaround is available.","aliases":["GHSA-6q4m-7476-932w"],"modified":"2026-08-12T03:51:14.789161107Z","published":"2023-03-13T20:19:23.350Z","database_specific":{"cwe_ids":["CWE-77"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27581.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/rlespinasse/github-slug-action/releases/tag/v4.4.1"},{"type":"WEB","url":"https://securitylab.github.com/research/github-actions-untrusted-input/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/27xxx/CVE-2023-27581.json"},{"type":"ADVISORY","url":"https://github.com/rlespinasse/github-slug-action/security/advisories/GHSA-6q4m-7476-932w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27581"},{"type":"FIX","url":"https://github.com/rlespinasse/github-slug-action/commit/102b1a064a9b145e56556e22b18b19c624538d94"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rlespinasse/github-slug-action","events":[{"introduced":"bd31a9f564f7930eea1ecfc8d0e6aebc4bc3279f"},{"fixed":"102b1a064a9b145e56556e22b18b19c624538d94"}],"database_specific":{"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.4.1"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:github-slug-action_project:github-slug-action:*:*:*:*:*:*:*:*"}}],"versions":["v4.4.0","v4.3.2","v4.3.1","v4.3.0","v4.2.5","4.2.5","4.2.4","4.2.3","4.2.2","4.2.1","4.2.0","4.1.0","4.0.1","4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-27581.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}